Remove Business Services Remove Exercises Remove Risk Remove Training
article thumbnail

Proposed Amendments to NY Financial Services Cybersecurity Regulations Impose New Obligations on Large Entities, Boards of Directors and CISOs

Hunton Privacy

As part of the “risk assessment” requirements under Section 500.9 of the Proposed Amendments, Class A Companies must use external experts to conduct a risk assessment at least once every three years. As part of the “training and monitoring” requirements under Section 500.14 The risk assessments required by Section 500.9

article thumbnail

NYDFS proposes significant cybersecurity regulation amendments

Data Protection Report

The proposed changes mark a turn by NYDFS toward more specific, granular and prescriptive requirements notably with respect to governance, risk assessments and asset inventories (detailed below). The draft amendments would also require that relevant employees be trained for their implementation. Cybersecurity Risk Assessments.